Remote printer spam made easy

By Robert Vamosi on 10 January 2008

Tags: network | printer | remote | security | spam

Security researcher Aaron Weaver claims visiting a random Web site could send unwanted print requests to your nearest office printer.

In a paper published in November (PDF), and cited on Wednesday in a blog by Jeremiah Grossman of White Hat Security, Weaver demonstrates the code necessary for sending a formatted page to a remote network printer, and, in an another example, to an intranet addressable fax machine. Since most network printers are behind the corporate firewall and therefore don't have security enabled, Weaver says that a simple iframe added to an Internet Web site could cause an internal network printer to start printing remotely.

The attack is derived from techniques employed within a project called hacking network printers by Adrian "Irongeek" Crenshaw. Weaver notes that most network printers listen on port 9100 and that you can telnet to port 9100, type text, and, once you disconnect, the text will print remotely. That's fine, but he ventures further that network printers also accept PostScript and Printer Control language (PCL) code as well, which creates more interesting printouts.

Weaver writes "within the last year there have been new discoveries on attacking the intranet from the Internet. This involves setting an image tag or script tag to an internally addressable IP address and then the browser will request the 'image' resource. Several attacks can be accomplished; port scanning, fingerprinting devices, and changing internal router settings."

Add to that list, printer spam. "The attack could be initiated by creating a hidden iframe, and then creating a form and submitting the contents to the printer. Since the connection will not close, a setTimeout could be used to cancel the request so that the printer would print the request."

As a demonstration, Weaver shows how to send an ASCII-drawn advertisement for frogs, and later, using PCL, a message in 20-point Courier: "Your printer is mine!"

One positive use for this would be for the IT or HR department to send a persistent banner reminding employees about the company's printer use policies. A negative use would be to remotely spam all the printers on the local intranet.

At the end of the short paper, Weaver offers some remediation. "First always have an administrator password set on your printer. Secondly look at restricting access to the printer so that it only accepts print jobs from a centralised print server."

Like this article? Click below to send it to your mobile for free!

Be the first to comment on this article!

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • Hacker talks fooling e-passport systems

  • Best free Windows Mobile software

  • Trend Micro PC-cillin Internet Security 2009

  • Norton Internet Security 2009: Photos

  • Trend Micro Internet Security 2009 Pro: Photos

  • 101 software tips, tweaks and tricks

  • Don't buy stand-alone antivirus: Trend Micro

  • Norton Internet Security 2009

  • Spyware Terminator

More articles »

Find the right software

Brand
  • Multiple options can be selected

    • Trend Micro PC-cillin Internet Security 2009

      Trend Micro PC-cillin Internet Security 2009

      You can't beat the price. For a good, basic internet security suite, we recommend Trend Micro Internet Security 2009.

    • Norton Internet Security 2009

      Norton Internet Security 2009

      Norton Internet Security 2009 hits all the right security notes and its superior protection technologies might even win back some jaded anti-Symantec folks, though the lack of adequate technical support may continue to frustrate.

    • Spyware Terminator

      Spyware Terminator

      This spyware scanner and removal tool does the job, but enabling some functions may cause slight slowdowns and it has a few bugs in Vista.

    • ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security 2009 provides top-notch security protection that is light on system resources, allowing you to work unencumbered.

    • Ad-Aware 2008

      Ad-Aware 2008

      This year's update to user favourite Ad-Aware is quite a significant overhaul, and the result is faster scan times and a new interface.

    More reviews »

    Membership benefits

    Contact community members

    Contact community members

    Add friends or tech gurus to you contacts and send them messages. Sign up for a free CNET.com.au membership now!